Sony had password recovery exploit, trying to hide it

This topic is locked from further discussion.

Avatar image for deactivated-5c79c3cfce222
deactivated-5c79c3cfce222

4715

Forum Posts

0

Wiki Points

0

Followers

Reviews: 3

User Lists: 0

#1 deactivated-5c79c3cfce222
Member since 2009 • 4715 Posts

Basically unathorized individuals could gain access to users' accounts simply by knowing their email and date of birth. The hole is in the process of being plugged after this guy informed Sony about it. Sony claims site is down for maintenence in order to improve mail sendout process/not telling the truth.

NeoGAF

Q. If I already reset my password am I safe?
A. The exploit was possible on any account the email and date of birth was known for, regardless of if the password was changed or not, or what region the account was tied to.

Q. What if they don't know my Date of Birth or Email account?
A. Then the average user would not be able to take your account, however due to the database being illegally accessed in April, it's safe to assume that someone, somewhere, has access to a large number of users details, which include date of birth and email addresses, this alone should be reason enough to change your email.

Q. Are you sure this is real?
A. Yes, it was demonstrated to one of our empty accounts, then we were able to repeat the process ourselves after figuring out the method, this was additionally confirmed when a twitter user provided us with his data and requested that we change his password as proof.
We have since emailed him his new password, and no other data on his account was changed.

Q. Can Sony fix it?
A. Shortly after containing SCEE, the online forms connected to login and password recovery for the PlayStation and other linked networks was shut down and placed in a maintenance mode, I can only assume this is a direct response to our detailed reports to SCEE, with that said, I assume that when services resume the exploit will be patched and everyone's data once again safe.

Q. If Sony fixes the hole should I worry?
A. I would suggest that everyone, regardless of if they have been affected or not, create a new password and change their account email to one they do not use anywhere else, and will not be sharing with anyone else just for additional security.

Q. Will you give us more details on the exploit?
A. Until we have confirmed that the security hole has been patched we will not release further details on how and why the exploit was possible.

SourceNylevia

Avatar image for MFDOOM1983
MFDOOM1983

8465

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#2 MFDOOM1983
Member since 2010 • 8465 Posts
Typical sony.
Avatar image for dipsetboy17
dipsetboy17

647

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#3 dipsetboy17
Member since 2009 • 647 Posts

ok they fixed it so what? it's nice he informed them about it.

Avatar image for Heil68
Heil68

60833

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

#4 Heil68
Member since 2004 • 60833 Posts
thats it, i want facial recognitions and fingerprint scans in ps4
Avatar image for SecretPolice
SecretPolice

45675

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#5 SecretPolice
Member since 2007 • 45675 Posts

Hmm, I guess Sony being phony is no baloney. :twisted:

:P

Avatar image for waltefmoney
waltefmoney

18030

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#6 waltefmoney
Member since 2010 • 18030 Posts

Lol @ Sony

Avatar image for Firebird-5
Firebird-5

2848

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#7 Firebird-5
Member since 2007 • 2848 Posts

sony is pathetic

Avatar image for blue_hazy_basic
blue_hazy_basic

30854

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

#9 blue_hazy_basic  Moderator
Member since 2002 • 30854 Posts
thats it, i want facial recognitions and fingerprint scans in ps4Heil68
:lol: this gave me a nice chuckle.
Avatar image for KevinnButlerNPK
KevinnButlerNPK

1145

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#10 KevinnButlerNPK
Member since 2010 • 1145 Posts

Wow you mean Super Network Kaz couldn't detect a backdoor exploit? According to String the Sony IT department is the greatest in the industry.....

Avatar image for Recarnator
Recarnator

229

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#11 Recarnator
Member since 2008 • 229 Posts

3rd game for free incoming.

Avatar image for catfishmoon23
catfishmoon23

5197

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#12 catfishmoon23
Member since 2005 • 5197 Posts

I had to use the feature before the first hack (you had to input your email and d.o.b. to reset your password). I had to because I forgot my password lol. I spent 20 million years trying to reset it though because I forgot I used a different year for my birthday because I was 16 when I signed up :P.

Avatar image for river_rat3117
river_rat3117

3474

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#13 river_rat3117
Member since 2003 • 3474 Posts
thats it, i want facial recognitions and fingerprint scans in ps4Heil68
That would be awesome a ps3 controller where the home button is a finger scanner and logs you on to your account based on your finger print
Avatar image for deactivated-5c79c3cfce222
deactivated-5c79c3cfce222

4715

Forum Posts

0

Wiki Points

0

Followers

Reviews: 3

User Lists: 0

#14 deactivated-5c79c3cfce222
Member since 2009 • 4715 Posts

ok they fixed it so what? it's nice he informed them about it.

dipsetboy17

So what? Despite all the external audits and whatnot, this exploit was first discovered by a guy on the internet. I can not trust that my details are secure on Sony's network and I can not trust that Sony is telling me the truth. That's kind of important.

Everyone's just real lucky a good guy reported it so quickly.

Avatar image for deactivated-5c79c3cfce222
deactivated-5c79c3cfce222

4715

Forum Posts

0

Wiki Points

0

Followers

Reviews: 3

User Lists: 0

#16 deactivated-5c79c3cfce222
Member since 2009 • 4715 Posts

Changed my PSN email just in case.

Avatar image for KevinnButlerNPK
KevinnButlerNPK

1145

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#17 KevinnButlerNPK
Member since 2010 • 1145 Posts

GiantBomb is reporting on it as well.

Why is Sony so incompetent?

Haziqonfire

But Howard Stringer said Kaz was the greatest IT professional in the world and being a high ranking Sony exec, you know he wouldn't be the least bit unbiased and know what he's talking about. I think Sony exists on their own planet.....

Avatar image for JohnF111
JohnF111

14190

Forum Posts

0

Wiki Points

0

Followers

Reviews: 12

User Lists: 0

#18 JohnF111
Member since 2010 • 14190 Posts
thats it, i want facial recognitions and fingerprint scans in ps4Heil68
yeah and a DNA analyser before the machine will even switch on, and voice recognition when the PS4 does switch on, and it should be able to detect stress incase someone is holding a gun to your head. Thats the right way to do things :lol: Hackers will always hack, nothing is safe and everything can be broken, if you can't deal with that then go live in a cave somewhere.
Avatar image for ethanradd
ethanradd

654

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#19 ethanradd
Member since 2009 • 654 Posts

#lolpsn

Avatar image for Giancar
Giancar

19160

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#20 Giancar
Member since 2006 • 19160 Posts

Isn´t it a phishing scam?

Avatar image for KarateeeChop
KarateeeChop

4666

Forum Posts

0

Wiki Points

0

Followers

Reviews: 4

User Lists: 0

#22 KarateeeChop
Member since 2010 • 4666 Posts

wow sony. pathetic.

Avatar image for ianuilliam
ianuilliam

4955

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#23 ianuilliam
Member since 2006 • 4955 Posts

[QUOTE="Heil68"]thats it, i want facial recognitions and fingerprint scans in ps4river_rat3117
That would be awesome a ps3 controller where the home button is a finger scanner and logs you on to your account based on your finger print

Wouldn't be impossible... small usb fingerprint scanners have been available for years, and are dirt cheap now.

Avatar image for jimmypsn
jimmypsn

4425

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#24 jimmypsn
Member since 2010 • 4425 Posts

Sony should stop playing games and stop trying to hide from their problems. Their brand is already tarnished. Man up Sony.